From aad311acbbab7805513ae2f57231fecb44d14df7 Mon Sep 17 00:00:00 2001 From: Pierre-Yves Chibon Date: Jan 19 2016 15:21:02 +0000 Subject: If there is no user associated with the username provided, bail out --- diff --git a/pagure/ui/login.py b/pagure/ui/login.py index 09f4f66..da14423 100644 --- a/pagure/ui/login.py +++ b/pagure/ui/login.py @@ -100,6 +100,9 @@ def do_login(): if form.validate_on_submit(): username = form.username.data user_obj = pagure.lib.search_user(SESSION, username=username) + if not user_obj: + flask.flash('Username or password invalid.', 'error') + return flask.redirect(flask.url_for('auth_login')) try: password_checks = check_password(